CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◉ Threat Intelligence Aug 07, 2026

July 2026 CVE Landscape

Recorded Future Archived Aug 07, 2026 ✓ Full text saved

In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month.

Full text archived locally
✦ AI Summary · Claude Sonnet


    This website utilizes technologies such as cookies to enable essential site functionality, as well as for analytics, personalization, and targeted advertising. To learn more, view the following link: Privacy Policy Manage Preferences Skip to main content <-- RECORDED FUTURE BLOG July 2026 CVE Landscape PUBLISHED ON 07 AUG 2026 Insikt Group® In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data. The 85 vulnerabilities in this report affected products from 61 vendors, with Microsoft accounting for approximately 12% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors. Insikt Group previously created a Nuclei template to detect the Langflow vulnerability (CVE-2025-3248) featured in this report. These are available to Recorded Future customers via the Recorded Future Intelligence Platform. Quick reference: July 2026 Vulnerability Table All 81 vulnerabilities below were actively exploited or operationally weaponized in July 2026. This table does not include the four CVEs that were primarily surfaced through our honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing. # Vulnerability Risk Score Vendor/Product KEV Analysis RCE PoC 1 CVE-2008-4128 99 Cisco IOS ✓ ✓ ✓ Link 2 CVE-2017-17215 99 Huawei HG532 ✓ ✓ ✓ Link 3 CVE-2018-0802 99 Microsoft Office Equation Editor ✓ ✓ ✓ Link 4 CVE-2021-4034 99 Polkit ✓ ✓ Link 5 CVE-2021-27137 99 DD-WRT ✓ ✓ ✓ Link 6 CVE-2023-4346 99 KNX Association KNX Protocol Connection Authorization Option 1 ✓ 7 CVE-2025-55182 99 Meta React Server Components ✓ ✓ ✓ Link 8 CVE-2025-68686 99 Fortinet FortiOS ✓ 9 CVE-2026-0770 99 Langflow ✓ ✓ ✓ Link 10 CVE-2026-15409 99 SonicWall SMA1000 Appliances ✓ ✓ Link 11 CVE-2026-15410 99 SonicWall SMA1000 Appliances ✓ ✓ ✓ Link 12 CVE-2026-16232 99 Check Point SmartConsole ✓ ✓ Link 13 CVE-2026-16812 99 Arista VeloCloud Orchestrator ✓ 14 CVE-2026-20316 99 Cisco Secure Firewall Management Center (FMC) ✓ 15 CVE-2026-25089 99 Fortinet FortiSandbox ✓ ✓ ✓ Link 16 CVE-2026-34486 99 Apache Tomcat ✓ 17 CVE-2026-39808 99 Fortinet FortiSandbox ✓ ✓ ✓ Link 18 CVE-2026-39987 99 Marimo ✓ ✓ ✓ Link 19 CVE-2026-46817 99 Oracle E-Business Suite ✓ ✓ Link 20 CVE-2026-48282 99 Adobe ColdFusion ✓ ✓ ✓ Link 21 CVE-2026-48907 99 JoomlaContentEditor.net Joomla Content Editor (JCE) ✓ ✓ ✓ Link 22 CVE-2026-48908 99 JoomShaper SP Page Builder ✓ ✓ ✓ Link 23 CVE-2026-48939 99 iCagenda ✓ ✓ ✓ Link 24 CVE-2026-50522 99 Microsoft SharePoint ✓ ✓ ✓ Link 25 CVE-2026-55255 99 Langflow ✓ ✓ Link 26 CVE-2026-56155 99 Microsoft Active Directory Federation Services ✓ 27 CVE-2026-56164 99 Microsoft SharePoint Server ✓ ✓ Link 28 CVE-2026-56290 99 Joomlack Page Builder ✓ ✓ ✓ Link 29 CVE-2026-56291 99 Balbooa Forms ✓ ✓ ✓ Link 30 CVE-2026-58644 99 Microsoft SharePoint ✓ ✓ 31 CVE-2026-60137 99 WordPress Core ✓ ✓ Link 32 CVE-2026-63030 99 WordPress Core ✓ ✓ ✓ Link 33 CVE-2021-3156 89 Sudo ✓ ✓ Link 34 CVE-2021-29441 89 Alibaba Nacos ✓ ✓ Link 35 CVE-2025-6389 89 Sneeit Framework ✓ ✓ ✓ Link 36 CVE-2025-9491 89 Microsoft Windows ✓ ✓ ✓ Link 37 CVE-2025-32432 89 Craft CMS ✓ ✓ ✓ Link 38 CVE-2025-3248 89 Langflow ✓ ✓ ✓ Link 39 CVE-2025-34152 89 Shenzhen Aitemi M300 Wi-Fi Repeater ✓ ✓ ✓ Link 40 CVE-2025-49113 89 Roundcube Webmail ✓ ✓ ✓ Link 41 CVE-2025-66376 89 Zimbra Collaboration ✓ 42 CVE-2026-0257 89 Palo Alto Networks PAN-OS and Prisma Access ✓ ✓ Link 43 CVE-2026-0740 89 SaturdayDrive Ninja Forms - File Uploads ✓ ✓ ✓ Link 44 CVE-2026-3055 89 NetScaler ADC and Gateway ✓ ✓ Link 45 CVE-2026-6875 89 ServiceNow AI Platform ✓ ✓ ✓ Link 46 CVE-2026-12569 89 PTC Windchill PDMLink and FlexPLM ✓ ✓ 47 CVE-2026-29014 89 MetInfo CMS ✓ ✓ ✓ Link 48 CVE-2026-42897 89 Microsoft Exchange Server 2016 CU23 and Subscription Edition RTM ✓ ✓ Link 49 CVE-2026-45659 89 Microsoft SharePoint Server ✓ ✓ 50 CVE-2026-31843 87 goodoneuz pay-uz ✓ ✓ 51 CVE-2013-3307 79 Linksys E1000, E1200, and E3200 ✓ ✓ 52 CVE-2016-20016 79 MVPower TV-7104HE and TV-7108HE DVRs ✓ ✓ ✓ Link 53 CVE-2017-5259 79 Cambium Networks cnPilot ✓ ✓ 54 CVE-2017-7269 79 Microsoft IIS ✓ ✓ ✓ Link 55 CVE-2018-11511 79 ASUSTOR ADM Photo Gallery ✓ ✓ Link 56 CVE-2018-14558 79 Tenda AC9, AC10, and AC7 firmware ✓ ✓ 57 CVE-2020-8515 79 DrayTek Vigor2960, Vigor300B, and Vigor3900 firmware ✓ ✓ ✓ Link 58 CVE-2020-22653 79 Ruckus APs, SmartZone, and ZoneDirector ✓ 59 CVE-2020-22658 79 Ruckus APs, SmartZone, and ZoneDirector ✓ 60 CVE-2020-25499 79 TOTOLINK A3002RU firmware ✓ ✓ ✓ Link 61 CVE-2020-36847 79 Eemitch Simple File List ✓ ✓ ✓ Link 62 CVE-2021-31755 79 Tenda AC11 firmware ✓ ✓ 63 CVE-2021-32305 79 WebSVN ✓ ✓ ✓ Link 64 CVE-2022-35733 79 UNIMO Technology UDR-JA1004, UDR-JA1008, and UDR-JA1016 digital video recorders ✓ ✓ 65 CVE-2023-25717 79 Ruckus Wireless Admin ✓ ✓ ✓ Link 66 CVE-2024-42009 79 RoundCube Webmail ✓ ✓ Link 67 CVE-2025-9528 79 Linksys E1700 ✓ ✓ ✓ Link 68 CVE-2025-12057 79 WavePlayer ✓ ✓ ✓ Link 69 CVE-2025-12352 79 Gravity Forms ✓ ✓ 70 CVE-2025-13486 79 Hwk-Fr Advanced Custom Fields: Extended ✓ ✓ ✓ Link 71 CVE-2025-28137 79 TOTOLINK A810R firmware ✓ ✓ ✓ Link 72 CVE-2026-1357 79 WPvivid Backup, Migration & Staging ✓ ✓ ✓ Link 73 CVE-2026-3395 79 MaxSite CMS ✓ ✓ ✓ Link 74 CVE-2026-3844 79 Cloudways Breeze Cache ✓ ✓ ✓ Link 75 CVE-2026-16723 79 Alibaba Fastjson ✓ ✓ ✓ Link 76 CVE-2026-29059 79 Windmill ✓ 77 CVE-2026-33824 79 Microsoft Windows IKE Extension ✓ ✓ 78 CVE-2021-24139 78 Photo Gallery by 10Web ✓ 79 CVE-2025-7852 78 Iqonic Design WPBookit ✓ ✓ 80 CVE-2026-1969 72 ThemeREX Addons WordPress plugin ✓ 81 CVE-2025-7443 71 BerqWP Automated Page Speed Optimization ✓ ✓ Table 1: List of vulnerabilities that were actively exploited in July, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs). Key trends: July 2026 In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure; Cloud Atlas abused Microsoft Equation Editor to deliver CloudAtlasGo; Armored Likho used a malicious Windows shortcut to deploy BusySnake Stealer; and JADEPUFFER and Cl0p targeted exposed AI and product-lifecycle platforms for encryption, data theft, and extortion. 57 of the 85 vulnerabilities enabled remote code execution (RCE), including flaws affecting Microsoft, Fortinet, Langflow, ServiceNow, WordPress, and Joomla ecosystems, internet-facing security appliances, and embedded network devices. We identified public proof-of-concept (PoC) exploits and scanners for 60 of the 85 vulnerabilities in this report. The most commonly observed weakness classes were CWE-78 (OS Command Injection), CWE-434 (Unrestricted Upload of File with Dangerous Type), CWE-94 (Code Injection), and CWE-502 (Deserialization of Untrusted Data). 14 of the 85 vulnerabilities in this month’s table are at least 5 years old, with the oldest approximately 18 years old, reinforcing how threat actors continue to exploit long-known weaknesses in environments where patching has lagged. Additionally, the fastest observed time from a vulnerability’s public disclosure to reported exploitation was less than one day. Trend analysis: Malware-Linked Exploitation Spans IoT, Email, and Enterprise Applications An Insikt Group® TTP Instance on the Dysphoria botnet linked CVE-2013-3307, CVE-2016-20016, CVE-2017-17215, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-35733, CVE-2025-28137, CVE-2025-34152, CVE-2025-55182, CVE-2025-9528 to the exploitation of routers, gateways, cameras, repeaters, and other embedded Linux devices. Dysphoria combined known RCE flaws with weak Telnet and Secure Shell credentials to enroll compromised systems into DDoS and relay infrastructure. Figure 1: Vulnerability Intelligence Card® for CVE-2017-17215 in Recorded Future (Source: Recorded Future) China-nexus activity showed a related interest in turning edge infrastructure into operational relay capacity. An Insikt Group® Validated Intelligence Event detailed how UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network. In both the Dysphoria and UAT-7810 campaigns, compromised devices were repurposed as relay infrastructure after initial access. Dysphoria used infected hosts to proxy traffic and obscure backend C2 infrastructure, while UAT-7810 expanded the LapDogs ORB network to support operations by other China-nexus actors. Email, document, and collaboration platforms were targeted for more focused espionage and payload delivery. A TTP Instance detailed how Cloud Atlas used malicious Office documents to exploit CVE-2018-0802 and deliver CloudAtlasGo. A Validated Intelligence Event detailed how UNK_MassTraction exploited CVE-2024-42009 in Roundcube and used IceCube during post-exploitation, where the malware attempted to exploit CVE-2025-49113. A TTP Instance detailed CL-STA-1114's abuse of CVE-2025-66376, and a Validated Intelligence Event detailed TA488's exploitation of CVE-2026-42897 to deploy OWAReaper. Separately, a Validated Intelligence Event detailed an Armored Likho campaign that used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer. Across these campaigns, attackers targeted communications and document workflows to access sensitive information and create opportunities for additional payload execution. Additional trends and analyses from July are available to Recorded Future customers. Take action Timely and relevant information on vulnerabilities in your environment and that of your vendors and suppliers is critical for reducing risk. Find out how Recorded Future can support your team by increasing visibility, improving efficiency, and enabling confident decisions. Vulnerability Prioritization – Prioritize vulnerabilities based on the likelihood of exploitation – not just the severity. Easily understand the risk of exploitation alongside severity, and real-time contextualized intelligence to help you quickly make confident decisions, patch what matters, and prevent attacks. Attack Surface Intelligence – Identify internet-facing assets vulnerable to a specific CVE. Attack Surface Intelligence provides an outside-in view of your organization to help you actively discover, prioritize, and respond to unknown, vulnerable, or misconfigured assets. Third-Party Risk – Gain an external view of the security posture of your vendors and partners. Eliminate time-consuming research and vendor communication cycles with the ability to promptly assess vulnerabilities in their internet-facing systems. Insikt Group® – Receive access to exclusive reports on new vulnerabilities and trends from Recorded Future’s team of experts, the Insikt Group®. Download Nuclei templates created by Insikt Group® for select CVEs to detect actively exploited vulnerabilities. Recorded Future Professional Services – Work with our Professional Services team on a Vulnerability Analysis Engagement. Designed to equip your team with advanced strategies for identifying, prioritizing, and mitigating threats effectively, this program delves into technologies and operations essential for a successful vulnerability management program. (Learn more about how our Professional Services team can help your elevate your team by watching our recent Vulnerability Prioritization Workshop) About Insikt Group® Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Their mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.
    💬 Team Notes
    Article Info
    Source
    Recorded Future
    Category
    ◉ Threat Intelligence
    Published
    Aug 07, 2026
    Archived
    Aug 07, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗